Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, February 5, 2014

Google Has Launched a For-Profit Privacy Invasion Into Our Electronic Lives

By Steven Rosenfeld
February 3, 2014 | AlterNet

No longer content to vacuum up, scan, index and sell analytics based on the content of our texts, emails, searches, locations and more, Google now has a new target: tapping, mapping and colonizing the networks wiring our lives.

Google argues that it has the right to collect your most sensitive data, as long as it flows across an open WiFi network,” PrivacySOS.org [3] said [4] last month after Google announced a $3.2 billion acquisition of Nest [5], which sells WiFi-controlled home heating appliances. “Now do you want to let this company inside your home?”

“Uhm… I hate to break this to the ACLU—given they’re supposed to be on the cutting edge of the privacy debate—but the thing is, Google’s already in our homes,” commented [6] PandoDaily’s Yasha Levine. “It has been in our homes for a long, long time. And not just in our homes, but at work, in our cars and even when we’re walking down the street.”

“As many have pointed out the privacy concerns of this development are huge,” wrote two other PandoDaily writers, Carmel Deamicus and Michael Carney. “Nest products track detailed information [7] about their users’ movements, in addition to things like a user’s WiFi IP address, and whether the specific address is a home or a business.”

Google is poised to cross another personal boundary. It is not just that our questions and queries are being aggressively collected, parsed, sold and resold, but that the networks tying together our digitized lives—via our devices, their settings and passwords—are also being eyed by the global data-hungry Goliath.
“The acquisition will help Google close the circle of search, people and goods in a broad Internet of Everything,” wrote [8] Wall Street Journal editor Michael Hickins. “As Aaron Levie, CEO of Box Inc. tweeted, ‘With home automation, self-driving cars, robots, mobile, and life sciences, Google is setting itself up to own the 21st century.’”

Anyone who cares about maintaining some degree of privacy should pay attention. Google has been doing a lot more than its lobbyists and executives have disclosed when defending or promoting its initiatives. Here are four examples that undescrore Google’s corporate ethos that any data it can grab is Google's for the taking.

  1. Street View: not just street mapping. After being sued by 38 states, Google admitted last March that its weird-looking cars outfitted with roof cameras facing four directions were not just taking pictures; they were collecting data from computers inside homes and structures, including “passwords, e-mails and other personal information from unsuspecting computer users,” the New York Times reported [9].
  2. Gmail: prying and spying. This October, a federal judge refused to dismiss a potential class-action lawsuit brought by Gmail users who objected to its practice of analyzing the content of all the messages on its network and selling byproducts to advertisers. Those suing Google said it violated federal wiretap laws.
    This issue isn’t new to Google. In congressional testimony in 2009, Google’s lawyers said [10] its email technology was used for scanning for spam, computer viruses and serving ads “within the Gmail user’s experience.” But last fall, U.S. District Court Judge Lucy Koh held that Google never told Gmail users that Google would create personal profiles and target users with ads. Nor did people who are not Gmail users, but who were writing to Gmail addresses, agree to let Google collect and parse their messages.
  3. Google Safari: not just hunting WiFi. Google’s court record includes more than just grabbing and snatching data. In early 2012, theWall Street Journal broke the story that its software was bypassing security settings for Apple devices using the Safari browser. “Google hated this [Safari’s anti-tracking features] and used a secret code to bypass this security setting,” the blog GoogleExposed wrote [11]. “This exposed millions of Safari users to tracking for months without them even knowing about it.” In August 2012, the Federal Trade Commission fined [12] Google $22.5 million, its largest civil fine, noting that Google also had violated previous privacy agreements.
  4. Android: another data gateway. One year after the FTC fine, ComputerWorld.com [13]’s Michael Horowitz, who writes its Defensive Computing feature, noted Google was back to its old tricks. “Google knows nearly every WiFi password in the world,” he declared, explaining that was the result of backdoor access to hundreds of millions of phones and devices using its Android operating system.
    “Sounds great. Backing up your data/settings makes moving to a new Android device much easier,” Horowitz wrote, citing how the company sold this feature to consumers. “It lets Google configure your new Android device very much like your old one. What is not said, is that Google can read the WiFi passwords.” The good news, he said, is that this feature can be turned off. “The bad news is that, like any American company, Google can be compelled by agencies of the U.S. government to silently spill the beans.”

ComputerWorld was careful [14] not to pick just on Google for domestic spying. DropBox, Microsoft, Apple, Yahoo, FaceBook, Skype—and others—all do pretty much the same thing: read user data and grant government access to it. But Google’s mission, detailed [15] in its patents, stands apart. Its business is based on analyzing user metrics with ever-growing [8] precision, and selling those insights to advertisers.

Thus, the recent handwringing [16] by Google CEO Eric Schmidt that Google—and others—was taken advantage of by America’s top spymasters following Edward Snowden’s still-unfolding National Security Agency whistleblowing, is more than hollow. It’s a farce. The record shows that Google knows exactly what it is doing.

2014 is likely to be a year where the trade-off for more profits and data for Google will be the loss of privacy. It’s not paranoid to say that Google’s acquisition of Nest is at the cutting edge of colonizing the links between our electronic devices and our lives. The trend of aggregating all the data that’s out there is behind many privacy-invading social media products, such as an app launching this week [17] that literally allows a man to walk into a bar, see a woman and know her name “before he even says hello."

Later this summer, Google will start selling its voice- and video-capturing Glass eyewear. Google Glass may be fantastic as a hands-liberating computing platform, but it also enables its users to film, analyze or spy upon others from afar. But it's up to us to say where the red lines should be drawn when it comes to protecting privacy and personal rights, and balacing those aganist overly intrusive individuals, corporations, institutions and governments.



Links:
[1] http://alternet.org
[2] http://www.alternet.org/authors/steven-rosenfeld
[3] http://privacysos.org/
[4] http://privacysos.org/node/1299
[5] https://nest.com/blog/2014/01/13/welcome-home/
[6] http://pando.com/2014/01/14/privacy-advocates-freak-out-at-googles-nest-acquisition-what-took-them-so-long/
[7] https://nest.com/legal/privacy-statement/
[8] http://blogs.wsj.com/cio/2014/01/14/the-morning-download-googles-nest-building-may-alarm-privacy-hawks/
[9] http://www.nytimes.com/2013/03/13/technology/google-pays-fine-over-street-view-privacy-breach.html
[10] http://www.nytimes.com/interactive/2013/10/02/technology/google-email-case.html
[11] http://googleexposed.wordpress.com/2012/04/18/huge-fine-against-google-for-violating-privacy-is-imminent/
[12] http://bits.blogs.nytimes.com/2012/08/09/f-t-c-fines-google-22-5-million-for-safari-privacy-violations/
[13] http://computerworld.com/
[14] http://blogs.computerworld.com/print/22300
[15] http://www.google.de/patents/EP1634206A4?hl=de&cl=en
[16] http://www.engadget.com/2013/11/04/eric-schmidt-slams-for-snooping/
[17] http://blogs.wsj.com/venturecapital/2014/01/30/socialradar-balances-privacy-with-new-social-geolocation-app/?KEYWORDS=google+privacy
[18] http://www.alternet.org/tags/google-0
[19] http://www.alternet.org/%2Bnew_src%2B

Tuesday, March 19, 2013

US to allow spy agencies to monitor citizens' finances

RT: March 14, 2013

Washington is reportedly considering opening all US financial records to national intelligence agencies in order to prevent future crimes. Only the FBI has had unlimited access to such databases; other agencies had to file case-by-case requests.

The Obama administration is preparing legislation to enable the country’s numerous security and intelligence agencies to spy on the accounts of US citizens, Reuters has revealed. The scheme’s stated aim is to help to identify and track terrorist cells, expose money-laundering schemes, trace criminal syndicates and curb corruption.

"It's a war on money, war on corruption, on politically exposed persons, anti-money laundering, organized crime," Amit Kumar, the UN advisor on Taliban and a fellow at the Democrat-established Center for National Policy think tank told Reuters.

The plan, dated March 4, is in its early stages but appears to have no judicial obstacles, as US legislation does not prohibit the exchange of information between government bodies. However, human rights activists have already criticized the plan

The planning document obtained by Reuters that the US Treasury’s financial database, which previously was only fully accessible by the FBI, will soon be integrated with national criminal, intelligence and other databases to become accessible to “law enforcement, counter-terrorism agencies, financial regulators and the intelligence community.”

Today, the US Treasury's Financial Crimes Enforcement Network (FinCEN) does not only collect data on clients of financial institutions, it also gathers reports of so-called ‘suspicious client activity’.

An estimated 25,000 financial institutions operating inside US territory – like banks, money transfer agencies, securities dealers and casinos – are obliged to report any activity considered suspicious, such as large (over $10,000) cash transfers, strangely account structures, computer hacking, counterfeiting and suspected money laundering.

The system is arranged so that if a bank is revealed to have not reported its clients’ suspicious activities, it risks of paying severe fines. Many banks err on the side of caution, and file reports on any activity deemed even slightly unusual: Every year, 15 million ‘suspicious activity reports’ are filed to the US Treasury, which allocates considerable resources to deal with them all.


If the Obama administration’s financial spy plan is enacted, US government agencies will have access to virtually all financial information on citizens or foreigners doing business in the US.

Currently, investigating a financial crime involves unraveling a tangle of evidence that could lead to a certain person, such as demanding a specific financial dossier from FinCEN. Once agencies like CIA, NSA or Counter Terrorism Center are allowed unrestricted access to FinCEN data, it would become possible for them to target an individual and arrest them for a crime for which they are not currently under investigation.

A US Treasury spokesperson vowed the agencies will adhere to safeguards outlined in both the Bank Secrecy Act and the US PATRIOT Act: “Law enforcement and intelligence community members with access to this information are bound by these safeguards.”

But Michael German, the senior policy counsel for the American Civil Liberties Union, told Reuters that “the intelligence community simply ignores the rules” when it comes to how sensitive information is used.

German recalled Congress had refused to approve a similar plan a decade ago, but now “the guidelines were subsequently loosened… It’s in a black hole.”

‘Citizens caught up in financial crosshairs’


The new plan will do little in increasing the efficacy of “keeping America safe,” while potentially increasing, at least partially, the risk of an innocent or “wrongly-profiled” individual being caught through a misreading of banking information, Margaret Bogenrief, a founding partner of ACM Partners financial advisory firm told RT.

“The continued efforts to 'keep its citizens safe,' the US government seems be to struggling to walk that line between protection and invasion of American citizens’ privacy,” Bogenrief said. “More citizens could end up being caught up in the financial crosshairs.”

Considering that financial institution are already over-reporting on questionable activity this new plan of enforcement and power “almost guarantees an abuse, whether intentional or not,” she added.

The true unintended tragedy of this plan is that it won’t bring a significant increase in arrests of high-profile criminals, Bogenrief believes.

“Truly sophisticated criminals – whether they be members of organized crime, gangs, or terrorist groups – will already have the structures and teams in place that will assist these criminal groups in both skirting these rules and avoiding prosecution.”

The Obama administration’s financial spying plan is a shocking attack on personal freedom, independent journalist and founder of Wide Awake News, Charlie McGrath says.“Sold as an effort to stop international terror groups, the proposed measure pushes us ever closer to a complete Orwellian Police State where you are guilty without cause, evidence, or even accusation,” McGrath told RT.

Sunday, July 24, 2011

Phone Hacking: US Authorities Preparing to Subpoena News Corp


Investigation launced into whether News Corp broke anti-bribery and hacking laws in US
by Ed Pilkington in New York 
 
The judicial screws are tightening on Rupert Murdoch's empire in America as the US justice department prepares to subpoena News Corporation in its investigation into whether the company broke anti-bribery and hacking laws on both sides of the Atlantic.

The Foreign Corrupt Practices Act forbids US-based companies from profiting from bribery in other countries. The news that subpoenas are being drawn up, reported by News Corp's flagship newspaper the Wall Street Journal, comes a week after attorney general Eric Holder said he was launching a preliminary investigation into the media group as a result of the UK phone-hacking scandal.

According to the Journal, the subpoenas will be broadly cast to draw information from the company relevant to the investigation, though final approval has yet to be granted by top justice department officials. In addition, it has emerged that federal prosecutors have begun probing allegations that News Corp's advertising arm in the US hacked into a computer of a competitor as part of a campaign to crush its rival.

A lawyer for the smaller company, Floorgraphics, told NBC he was visited by two federal prosecutors and an FBI agent. News Corp declined to comment on the legal moves.

Mary Mulligan, a former federal prosecutor in the southern district of New York that handles many of the big corporate cases of this sort, said there were numerous directions in which the probe of News Corp could go. "This is a complicated investigation, and a very important matter that's being looked into." She said the FBI and other federal agents would be guided by what they found.

"The facts are going to drive any charges that arise – what was accessed, how it was accessed and where."

One specific allegation that the FBI is investigating is whether News of the World journalists tried to access the phone records of 9/11 victims. The claim was raised in the UK's Daily Mirror, though, so far, no solid evidence has emerged to support it. If the accusations are confirmed, News Corp could be susceptible to prosecution under Title 18 USC 2701, involving unlawful access to stored communications, or 2703 and 2704 if the mobile phone messages are found to have been stored on a separate server.

News Corp also faces a possibly lengthy and costly federal probe into whether it broke anti-bribery laws as part of the illegal News of the World phone hacking in the UK.

The company is potentially liable under the Foreign Corrupt Practices Act (FCPA), which bans US-based companies from profiting from bribery and corruption in other countries.

News Corp is a US-based firm, its headquarters on Sixth Avenue in Manhattan.

FCPA experts have suggested that it could be brought under the auspices of the act because News of the World journalists bribed police officers in the UK in search of exclusive stories that in turn increased sales and generated profits.

It is not a defence for News Corp executives to argue that they were unaware of the bribery. Under the FCPA, a company can still be penalised if it should have known – what is called "willful blindness".

News Corp could also come under the scrutiny of the US Securities and Exchange Commission (SEC), which is jointly responsible with the justice department for policing the FCPA.

The SEC will want to know whether News Corp properly declared all its activities in its accounts or whether it tried to hide any bribes made within the UK under false accounting returns.

It is not known precisely what information investigators are seeking from News Corp under the subpoenas, but it could include News of the World accounts which would then be examined by forensic accountants.

News Corp itself seems to be most anxious about the FCPA side of the federal investigations, judging from the legal team it has assembled – some of the heaviest hitters in American legal affairs.

They include Brendan Sullivan, a formidable trial lawyer once described as "the legal equivalent of nuclear war", and Mark Mendelsohn, who used to head the justice department section that decides which FCPA cases to prosecute. He is joined by Michael Mukasey, a former US attorney general, and his legal partner Mary Jo White, who represented Siemens in one of the largest FCPA cases ever.

The Siemens case underlined how serious an FCPA prosecution could be for News Corp. In 2008, the engineering company admitted bribing foreign officials around the world and paid a record $800m (£490m) in settlement. That included $350m in disgorgement – a repayment for the profits it was estimated to have made as a result of the bribery.

No figure exists for how much money News of the World made out of its phone hacking activities. Under the FCPA, a rough calculation would be made which News Corp could be forced to disgorge.

Monday, January 10, 2011

Hackers find new way to cheat on Wall Street

Hackers find new way to cheat on Wall Street -- to everyone's peril
Published on 01-10-2011
Source: InfoWorld

High-frequency trading networks, which complete stock market transactions in microseconds, are vulnerable to manipulation by hackers who can inject tiny amounts of latency into them. By doing so, they can subtly change the course of trading and pocket profits of millions of dollars in just a few seconds, says Rony Kay, a former IBM research fellow and founder of cPacket Networks, a Silicon Valley firm that develops chips and technologies for network monitoring and traffic analysis.

Kay, an Israeli-born computer scientist and one-time Intel engineering manager, says the root of the problem is the increasing speed of networks; as they get faster and faster, our ability to actually understand events taking place within them isn't keeping up. Network monitoring technology can detect perturbations in network traffic happening in milliseconds, but when changes occur in microseconds, they're not visible, he says.

cPacket has developed a proof of concept showing that these side-channel attacks can be used to create tiny delays in the transmission of market data and trades. By manipulating specific trading activities by several microseconds, an attacker could gain unfair trading advantage. And because the operation occurs outside the range of monitoring technology, it would remain invisible. "We believe that such techniques pose a substantial risk of creating unfair trading, if used by the wrong people," Kay says.

(A side-channel attacker looks at indirect information related to the computer -- the electromagnetic emanations from screens or keyboards, for example -- to determine what is going on in the machine. )

Latency threatens other applications as well

The lack of visibility into high-speed networks is of concern to more than the financial community. Managing traffic on today's 10Gbps and faster networks is becoming difficult, resulting in degradations of performance, particularly to virtualized systems. "It's difficult to take corrective actions when you can't really see what's taking place," Kay says. "If you cannot measure network latency, you cannot control it and cannot improve it."

In a PDF whitepaper on latency, Kay wrote, "Traditionally, applications that have latency requirements include: VoIP and interactive video conferencing, network gaming, high-performance computing, cloud computing, and automatic algorithmic trading. For example, one-way latency for VoIP telephony should generally not exceed 150 milliseconds (0.15 seconds) to enable good conversation quality, while interactive games typically require latencies between 100 and 1,000 milliseconds. However, the requirements for automated algorithmic trading are much more strict. A few extra milliseconds, or even a few extra microseconds, can enable trades to execute ahead of the competition, thereby increasing profits."

Indeed, latency, even at the very highest speeds, is so concerning that researchers at MIT recommended  any organization dealing in complicated time-sensitive global interactions should take a hard look at where they locate their data centers.

The MIT researchers even suggested that financial firms could gain some advantage by taking advantage of limitations posed by the speed of light. For example, it typically takes about 50 milliseconds to send a message from New York to London. Placing a server between the two could cut the speed of communication in half, they said, which may be enough time to take advantage of some momentary pricing discrepancy. Trading on that discrepancy is known as arbitrage, and it's becoming increasingly common.

Lessons of the "flash crash"

The vulnerability of markets in which high-frequency trading is common became all too evident last May, when exchanges experienced a "flash crash" that drove the Dow Jones down about 600 points in just five minutes. The incident was not the result of deliberate manipulation, but it shows just how dependant the financial world is on technology it doesn't really understand.

"Financial institutions and exchanges with [high-frequency trading] are spending millions to improve latency by microseconds and at the same time can't measure the data at that resolution in real time. It's disturbing," Kay says.

A side-channel attack on a high-frequency trading network is analogous to a denial-of-service attack. In a typical DoS attack, bots flood a target website with enormous numbers of hits, often causing a crash. A side-channel attack would be infinitely more subtle, but it would still function by adding extraneous packets to a legitimate data stream. Those extra packets slow the data just enough to give someone else a chance to move first in the market.

Kay says he does not know if anyone has yet launched a side-channel attack against a high-frequency trading network -- but it worries him. And it worries me. Financial markets are supposed to be a level playing field. They're not, of course. Small players, like the millions of us who invest for our 401(k)s and other retirement accounts, are at an immense disadvantage even when everything is kosher. But the proliferation of high-frequency trading widens the gap even more. If someone can really take advantage of a weakness in those networks, we're all really in trouble. And that's just another reason why more -- not less -- regulation is required in the financial markets.

Wednesday, March 31, 2010

Hacking Weak Passwords

As my email got hacked recently, this is timely...

***

How I’d Hack Your Weak Passwords
Internet standards expert, CEO of web company iFusion Labs, and blogger John Pozadzides knows a thing or two about password security—and he knows exactly how he'd hack the weak passwords you use all over the internet.
Note: This isn't intended as a guide to hacking *other people's* weak passwords. Instead, the aim is to help you better understand the security of your own passwords and how to bolster that security.
If you invited me to try and crack your password, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it?
Let's see… here is my top 10 list. I can obtain most of this information much easier than you think, then I might just be able to get into your e-mail, computer, or online banking. After all, if I get into one I'll probably get into all of them.
  1. Your partner, child, or pet's name, possibly followed by a 0 or 1 (because they're always making you use a number, aren't they?)
  2. The last 4 digits of your social security number.
  3. 123 or 1234 or 123456.
  4. "password"
  5. Your city, or college, football team name.
  6. Date of birth – yours, your partner's or your child's.
  7. "god"
  8. "letmein"
  9. "money"
  10. "love"
Statistically speaking that should probably cover about 20% of you. But don't worry. If I didn't get it yet it will probably only take a few more minutes before I do…
Hackers, and I'm not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, is the password you choose. (Ironically, the best protection people have is usually the one they take least seriously.)
One of the simplest ways to gain access to your information is through the use of a Brute Force Attack. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials. Insecure.org has a list of the Top 10 FREE Password Crackers right here.
So, how would one use this process to actually breach your personal security? Simple. Follow my logic:
  • You probably use the same password for lots of stuff right?
  • Some sites you access such as your Bank or work VPN probably have pretty decent security, so I'm not going to attack them.
  • However, other sites like the Hallmark e-mail greeting cards site, an online forumyou frequent, or an e-commerce site you've shopped at might not be as well prepared. So those are the ones I'd work on.
  • So, all we have to do now is unleash Brutuswwwhack, or THC Hydra on their server with instructions to try say 10,000 (or 100,000 – whatever makes you happy) different usernames and passwords as fast as possible.
  • Once we've got several login+password pairings we can then go back and test them on targeted sites.
  • But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser's cache. (Read this post to remedy that problem.)
And how fast could this be done? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker's computer, and the speed of the hacker's Internet connection.
Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it's just a matter of time before the computer runs through all the possibilities – or gets shut down trying.
Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters – like @#$%^&*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.










Remember, these are just for an average computer, and these assume you aren't using any word in the dictionary. If Google put their computer to work on it they'd finish about 1,000 times faster.
Now, I could go on for hours and hours more about all sorts of ways to compromise your security and generally make your life miserable – but 95% of those methods begin withcompromising your weak password. So, why not just protect yourself from the start and sleep better at night?
Believe me, I understand the need to choose passwords that are memorable. But if you're going to do that how about using something that no one is ever going to guess AND doesn't contain any common word or phrase in it.
Here are some password tips:
  1. Randomly substitute numbers for letters that look similar. The letter ‘o' becomes the number ‘0′, or even better an ‘@' or ‘*'. (i.e. – m0d3ltf0rd… like modelTford)
  2. Randomly throw in capital letters (i.e. – Mod3lTF0rd)
  3. Think of something you were attached to when you were younger, but DON'T CHOOSE A PERSON'S NAME! Every name plus every word in the dictionary will fail under a simple brute force attack.
  4. Maybe a place you loved, or a specific car, an attraction from a vacation, or a favorite restaurant?
  5. You really need to have different username / password combinations for everything. Remember, the technique is to break into anything you access just to figure out your standard password, then compromise everything else. This doesn't work if you don't use the same password everywhere.
  6. Since it can be difficult to remember a ton of passwords, I recommend usingRoboform for Windows users. It will store all of your passwords in an encrypted format and allow you to use just one master password to access all of them. It will also automatically fill in forms on Web pages, and you can even get versions that allow you to take your password list with you on your PDA, phone or a USB key. If you'd like to download it without having to navigate their web site here is the direct download link.(Ed. note: Lifehacker readers love the free, open-source KeePass for this duty, whileothers swear by the cross-platform, browser-based LastPass.)
  7. Mac users can use 1Password. It is essentially the same thing as Roboform, except for Mac, and they even have an iPhone application so you can take them with you too.
  8. Once you've thought of a password, try Microsoft's password strength tester to find out how secure it is.
By request I also created a short RoboForm Demonstration video. Hope it helps…
Another thing to keep in mind is that some of the passwords you think matter least actually matter most. For example, some people think that the password to their e-mail box isn't important because "I don't get anything sensitive there." Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank's Web site and tell it I've forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?
Often times people also reason that all of their passwords and logins are stored on their computer at home, which is safe behind a router or firewall device. Of course, they've never bothered to change the default password on that device, so someone could drive up and park near the house, use a laptop to breach the wireless network and then try passwords from this list until they gain control of your network — after which time they will own you!
Now I realize that every day we encounter people who over-exaggerate points in order to move us to action, but trust me this is not one of those times. There are 50 other ways you can be compromised and punished for using weak passwords that I haven't even mentioned.
I also realize that most people just don't care about all this until it's too late and they've learned a very hard lesson. But why don't you do me, and yourself, a favor and take a little action to strengthen your passwords and let me know that all the time I spent on this article wasn't completely in vain.
Please, be safe. It's a jungle out there.
EDIT: You might also want to listen to my interview on Connecticut Public Radio about password security.